logo

StorageCrypt ransomware, a coinminer and more

ID: bb1e73c4-c3f2-554a-841c-8ca55f6cdeb3

STIX ID: report--bb1e73c4-c3f2-554a-841c-8ca55f6cdeb3

Feed Name: Blaze's Security Blog

Threat Score
72/100

Date Published: 2017-12-06

Date Updated: 2026-04-19

Author: Bart

...
...

Analysis of a campaign associated with “StorageCrypt” shows a Windows component (“美女与野兽.exe”) exhibiting worm/backdoor behavior and a Linux intrusion chain exploiting SambaCry (CVE-2017-7494) to download additional payloads, chiefly a Monero miner with a watchdog, from C2 45.76.102.45; indicators include multiple filenames and hashes, pool config (xmr.pool.minergate.com:45560), and the user email [email protected]. While ransomware is referenced, the observed artifacts primarily perform coin-mining and backdoor activities; immediate patching of Samba is advised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.